CVE-2022-2085
Summary
| CVE | CVE-2022-2085 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-16 18:15:00 UTC |
| Updated | 2023-09-17 07:15:00 UTC |
| Description | A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64, mem_x_device is used and does not have an init_device_procs defined. This flaw allows an attacker to parse a large number of bits (more than 64 bits per pixel), which triggers a NULL pointer dereference flaw, causing an application to crash. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: ghostscript-9.56.1-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| GPL Ghostscript: Multiple Vulnerabilities (GLSA 202211-11) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| 2095261 – (CVE-2022-2085) CVE-2022-2085 ghostscript: Null pointer dereference in gx_default_create_buf_device() |
MISC |
bugzilla.redhat.com |
|
| git.ghostscript.com Git - ghostpdl.git/commit |
MISC |
git.ghostscript.com |
|
| git.ghostscript.com Git - ghostpdl.git/commit |
MISC |
git.ghostscript.com |
|
| [SECURITY] Fedora 35 Update: ghostscript-9.56.1-1.fc35 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| 704945 – Null pointer dereference in gx_default_create_buf_device() |
MISC |
bugs.ghostscript.com |
|
| GPL Ghostscript: Multiple Vulnerabilities (GLSA 202309-03) — Gentoo security |
MISC |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182693 Debian Security Update for ghostscript (CVE-2022-2085)
- 198965 Ubuntu Security Notification for Ghostscript Vulnerabilities (USN-5643-1)
- 283025 Fedora Security Update for ghostscript (FEDORA-2022-d287230630)
- 354420 Amazon Linux Security Advisory for ghostscript : ALAS2022-2022-230
- 354557 Amazon Linux Security Advisory for ghostscript : ALAS-2022-230
- 355242 Amazon Linux Security Advisory for ghostscript : ALAS2023-2023-053
- 710680 Gentoo Linux GPL Ghostscript Multiple Vulnerabilities (GLSA 202211-11)
- 710748 Gentoo Linux GPL Ghostscript Multiple Vulnerabilities (GLSA 202309-03)